Red Hat CNA-LR concluded that this CVE is not valid.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Disable or restrict preview token usage to prevent unauthorized album cover access
- Add authorization checks to the AlbumCover handler so that only users who own or are authorized for the album may view its cover image
- Review user session and token issuance policies to ensure only legitimate users possess preview tokens and consider revoking or rotating tokens
Generated by OpenCVE AI on August 11, 2026 at 17:21 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Mon, 17 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | PhotoPrism PhotoPrism - Insecure Direct Object Reference | |
| Metrics |
ssvc
|
Mon, 17 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Mon, 17 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo of any album. The AlbumCover handler does not verify that the requesting user is authorized to access the specified album before serving the cover image. An attacker with any valid preview token can enumerate and download album cover images belonging to other users. | Red Hat CNA-LR concluded that this CVE is not valid. |
Tue, 11 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Photoprism
Photoprism photoprism |
|
| Vendors & Products |
Photoprism
Photoprism photoprism |
Tue, 11 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo of any album. The AlbumCover handler does not verify that the requesting user is authorized to access the specified album before serving the cover image. An attacker with any valid preview token can enumerate and download album cover images belonging to other users. | |
| Title | PhotoPrism PhotoPrism - Insecure Direct Object Reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: TuranSec
Published:
Updated: 2026-08-17T14:04:05.864Z
Reserved: 2026-08-10T10:32:49.080Z
Link: CVE-2026-72540
Updated:
Status : Rejected
Published: 2026-08-11T12:17:39.347
Modified: 2026-08-17T14:20:22.083
Link: CVE-2026-72540
No data.
OpenCVE Enrichment
Updated: 2026-08-11T17:30:16Z
No weakness.